-
-
Notifications
You must be signed in to change notification settings - Fork 0
For Providers and Government
On Record should complement—not duplicate—HMIS, coordinated entry, Shelter Ready, or case-management systems. The public layer is not a place to upload client records, publish bed counts, or assign a provider score.
- Use individual accounts, role-based/attribute-based access, MFA, least privilege, confidentiality agreements, training, offboarding, encryption, and append-only audit logs.
- Keep identity, health, victim-service, recovery, and case data in protected systems.
- Route structured offers through moderation; do not expose a person to open comment threads.
- Use neutral response events and give the requester a correction/appeal path.
- Label freshness, eligibility, capacity, and provenance; never imply a placement guarantee.
- Publish a plain-language notice, retention schedule, complaint route, incident plan, and accessibility options before intake.
Any connector requires a data-sharing agreement, permitted-use matrix, current HUD/CoC mapping, legal and privacy review, synthetic tests, rollback, and a named owner. Victim-service providers may require a separate workflow under VAWA/FVPSA or other confidentiality rules. If the boundary cannot be documented, do not integrate.
Show acknowledged, deferred, referred, scheduled, completed, declined, expired, and withdrawn events with context. Do not infer moral failure from non-response. Let providers correct records, but do not let them unilaterally declare a requester’s need resolved.
On Record is a prototype. Do not enter real protected information. Guidance should be reviewed before each pilot or distribution. Return to Home · Report a security issue
About the site
Audience guides
Commitments and tools
Governance and technical
Participation